Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Cisco Secure ACS EAP-Response Packet Parsing Denial of Service Vulnerability

Cisco Secure ACS is prone to a denial-of-service vulnerability because it fails to properly validate user-supplied input.

An attacker can exploit this issue to crash the CSRadius and CSAuth processes, denying service to legitimate users. Given the nature of this issue, the attacker may also be able to run arbitrary code, but this has not been confirmed.

This vulnerability is documented in Cisco bug ID CSCsq10103.







 

Privacy Statement
Copyright 2009, SecurityFocus